Patentable/Patents/US-12699783-B2
US-12699783-B2

Encrypting data at rest and data in motion with trustworthy energy awareness

PublishedAugust 4, 2026
Assigneenot available in USPTO data we have
Technical Abstract

Energy aware data encryption operations are disclosed. An awareness engine includes models configured to generate a recommendation that includes an encryption time and/or an encryption model. When the encryption operation is a data at rest encryption operation, the data is encrypted in accordance with the recommendation and stored at the storage system. When the encryption operation is a data in motion encryption operation, the data is encrypted and transmitted to a target storage system in accordance with the recommendation. At the target storage system, the encrypted may be stored in an encrypted form or decrypted and stored. The recommendations are configured to account for energy considerations including energy cost and/or energy source.

Patent Claims

Legal claims defining the scope of protection, as filed with the USPTO.

1

requesting a recommendation for performing a data at rest encryption operation to encrypt data at a storage system, wherein the recommendation is requested from an awareness engine that includes an encryption model configured to estimate an encryption time, wherein the recommendation includes the encryption time and/or an encryption module; encrypting the data using the encryption module recommended by an awareness engine and according to the encryption time, wherein the encryption time determined by the awareness engine accounts for an energy cost associated with performing the data at rest encryption operation; and storing the encrypted data at the storage system. . A method comprising:

2

claim 1 . The method of, wherein the encryption time comprises an encryption time window and an estimated time to perform the encryption operation.

3

claim 1 . The method of, further comprising generating the encryption time by inputting features including weather features, and features of the storage system into a trained encryption module configured to predict the encryption time.

4

claim 2 . The method of, further comprising waiting for the encryption time window to arrive prior to performing the encryption operation.

5

claim 1 . The method of, wherein the encryption time is generated by at least one machine learning model trained on data associated with historical data at rest encryption operations, historical energy costs, and factors influencing the energy costs.

6

claim 1 . The method of, further comprising accounting for a source of energy or an estimated cost of the energy when performing the encryption operation.

7

claim 1 . The method of, wherein the encryption time is associated with lower energy costs.

8

claim 1 . The method of, further comprising recommending the encryption module from among a plurality of available encryption modules.

9

claim 1 . The method of, further comprising performing the data at rest encryption operation with an available encryption module when the encryption module recommended by the awareness engine does not satisfy encryption requirements of the storage system.

10

requesting a recommendation for performing a data in motion encryption operation at a storage system, wherein the recommendation is requested from an awareness engine that includes an encryption model configured to estimate an encryption time, wherein the recommendation includes the encryption time and/or an encryption module; encrypting the data using the encryption module recommended by an awareness engine and according to the encryption time, wherein the encryption time determined by the awareness engine accounts for an energy cost associated with performing the data at rest encryption operation; transmitting the encrypted data to a target storage system; decrypting the encrypted data at the target storage system; and storing the decrypted data at the target storage system. . A method comprising:

11

claim 10 . The method of, wherein the encryption time comprises an encryption time window and an estimated time to perform the encryption operation.

12

claim 10 . The method of, further comprising generating the encryption time by inputting features including weather features, and features of the storage system into a trained encryption module configured to predict the encryption time.

13

claim 11 . The method of, further comprising waiting for the encryption time window to arrive prior to performing the encryption operation.

14

claim 10 . The method of, wherein the encryption time is generated by at least one machine learning model trained on data associated with historical data in motion encryption operations, historical energy costs, and factors influencing the energy costs.

15

claim 10 . The method of, further comprising accounting for a source of energy or an estimated cost of the energy when performing the data in motion encryption operation.

16

claim 10 . The method of, wherein the encryption time is associated with lower energy costs.

17

claim 10 . The method of, further comprising recommending the encryption module from among a plurality of available encryption modules.

18

claim 17 . The method of, further comprising performing the data in motion encryption operation with an available encryption module when the recommended encryption module does not satisfy encryption requirements of the storage system.

19

requesting a recommendation for performing an encryption operation to encrypt data at a storage system, wherein the recommendation is requested from an awareness engine that includes an encryption model configured to estimate an encryption time, wherein the recommendation includes the encryption time and/or an encryption module; encrypting the data using the encryption module recommended by the awareness engine and according to the encryption time, wherein the encryption time determined by an awareness engine accounts for an energy cost associated with performing the data at rest encryption operation; and storing the encrypted data at the storage system. . A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:

20

claim 19 . The non-transitory storage medium of, further comprising transmitting the encrypted data to a target storage system, decrypting the encrypted data, and storing the decrypted data at the target storage system.

Detailed Description

Complete technical specification and implementation details from the patent document.

Embodiments of the present invention generally relate to systems and methods for encrypting and/or decrypting data. More particularly, at least some embodiments of the invention relate to systems, hardware, software, computer-readable media, and methods for encrypting data at rest and/or data in motion with energy awareness.

Data encryption typically refers to the process of encoding data from plaintext to ciphertext and data decryption refers to the process of generating the original plaintext from the ciphertext. Encryption can prevent unauthorized users from accessing or viewing the original data in plaintext. Advanced encryption standard (AES) is an example of a symmetric encryption algorithm and public key cryptography is an example of asymmetrical encryption.

Data at rest encryption (DARE) relates to the encryption of data that is stored in a storage system (e.g., in a database) and is not moving through networks. In certain storage arrays multiple options exist to encrypt data. Hardware-based encryption methods are often chosen as they are specifically designed for low latency encryption and for offloading computations from the CPU. However, encryption methods do not account for the energy required to encrypt the data.

Data in motion encryption (DIME) is the process of encrypting data for transmission between two or more points (e.g., from a source storage array to a target storage array). In the context of data in motion encryption, the encryption/decryption operations are performed by an encryption/decryption module (e.g., a cryptographic Application-Specific Integrated Circuit (ASIC)), which is configured specifically for the purpose of encryption/decryption operations. Similar to data at rest encryption/decryption operations, the encryption/decryption operations performed in data in motion operations are performed without accounting for the energy required to perform these operations.

Embodiments of the present invention generally relate to encrypting data at rest and/or encrypting data in motion. More particularly, at least some embodiments of the invention relate to systems, hardware, software, computer-readable media, and methods for encrypting/decrypting data with energy awareness. Energy awareness may include encrypting/decrypting data when energy costs are low, to encourage or consume green (e.g., renewable) energy, or other energy related.

Storage systems, including storage arrays, are generally configured to store data. For various reasons, data may be stored in an encrypted form. If the data is required by an application, the data may be decrypted. Encryption operations consume energy when performed.

Embodiments of the invention relate to encrypting data in an energy aware manner. Embodiments of the invention are discussed in the context of data encryption, but may be applied to data decryption. Embodiments of the invention relate to encrypting data at rest and to encrypting data in motion in an energy aware manner. The encryption operation may be performed in a manner that accounts for energy considerations, such as energy source, energy cost, grid conditions, or the like. Embodiments of the invention advantageously improve encryption operations by accounting for the time required to perform the encryption operation, a time to initiate or start the encryption operation, energy use, energy cost, energy sources, and/or other considerations.

1 FIG. 1 FIG. 106 116 126 106 116 discloses aspects of encrypting data with energy awareness.generally relates to (i) a modelconfigured to estimate or predict a recommendation for data at rest encryption, which recommendation may include a time required to perform the encryption operation, a time at which the encryption operation may be started, and/or a recommended encryption module, (ii) a modelconfigured to estimate or predict a recommendation for data in motion encryption, which recommendation may include a time required to perform the encryption operation, a time at which to start the encryption operation, and/or a recommended encryption module, and (iii) a modelconfigured to estimate aspects of energy awareness such as energy cost for one or more starting times or time windows. The modelsandmay also be configured to identify an encryption module or algorithm.

106 116 126 These models may be independent or combined. For example, a model may be trained to account for whether the encryption operation is a data at rest encryption operation or a data in motion encryption operation for purposes of determining an encryption time and/or an encryption module. The encryption time and/or encryption module recommended by the modelsand/ormay be input to the energy modelsuch that the recommended encryption time and encryption module are energy aware.

106 126 For example, the encryption time generated by the modelmay indicate that an hour is required to encrypt the data at rest or in motion using a particular encryption module. The modelmay predict energy costs for various times (e.g., the next 6 hours). This may enable the encryption operation to begin at an appropriate time to account for energy considerations or when energy cost is lowest or when renewable energy is being contributed to the grid.

1 FIG. 104 114 124 102 112 122 106 116 126 102 104 102 106 More specifically,illustrates a model, a model, and a modelthat are trained, respectively, with training datasets,, and, to generate trained models,, and. The training datasetincludes historical data related to previously performed (historical) data at rest encryption operations that can be used to train the modelto predict or estimate an encryption time (e.g., duration, and starting time of the encryption operation). The training datasetmay include information (e.g., features) describing or related to data that was encrypted that may include, but are not limited to, size of the data to be encrypted, time required to access the data, storage system features, available memory or computing resources, recommended encryption type or module, features of the network, geographic location of the data being encrypted, or the like. This information or various combinations thereof resulted in a trained modelconfigured to predict or estimate a time required to encrypt the data, a time to start the encryption operation, and/or a recommended module to perform the encryption operation.

112 114 116 112 104 114 116 114 The training datasetmay include historical data that can be used to train the modeland generate the trained model. The training datasetmay include historical aspects or features related to data in motion encryption operations. In addition to the features considered by the model, the modelmay also consider aspects of the encryption operation such as features of the source storage and the target storage, network conditions, or the like. The features may include a data size of the data to be encrypted, source information (e.g., hardware specifications), target information, network information (e.g., bandwidth), location data of the source and the target storage systems, or the like. The trained model, which results from training the model, is capable of predicting or recommending an encryption time and/or an encryption module.

122 124 122 The training datasetmay include data that can be used to train the model. The training datasetmay include historical weather data, historical energy costs (renewable and nonrenewable), energy production data (energy produced from renewable/non-renewable sources), historical watt energy supplied to the grid from renewable and nonrenewable sources, and the like.

126 The trained modelcan, using current and/or forecasted weather data and/or current and/or forecasted energy data, predict, estimate, or infer an energy source, cost of energy, or the like at various points in time.

106 116 126 106 116 126 126 130 106 116 126 Generally, the models,, andmay generate predictions or estimates that allow decisions to be made regarding an encryption operation with energy awareness. In one example, outputs of the modeland/or the modelmay be input to the model. The modelmay generate a recommendationthat accounts for the encryption time, encryption location, encryption source/target, and/or energy characteristics or considerations. The models,, andmay be combined in other manners.

106 116 120 In another example, the modelmay be configured to predict an encryption time for performing the encryption operation for either of a data at rest encryption operation and a data in motion operation and the modelis trained to recommend a specific encryption module or algorithm. When the model generates probabilities, the most likely encryption module and/or other potential encryption modules can be identified. As a result, the output of the awareness enginemay generate various combinations of encryption times/encryption modules that can be presented to the storage array. The storage array can select the combination from among the recommended combinations.

106 116 126 120 106 116 126 Generally, regardless of how the models,, andinteract or are connected, the awareness enginemay use the outputs of the trained models,, andseparately, in a chained manner, or the like, to provide recommendations regarding data at rest encryption operations and/or data in motion encryption operations.

130 120 120 The recommendationgenerated by the awareness enginemay account for energy cost, energy source or the like, the source used for the encryption operation, the target of the encryption operation (which may also be the source storage system (for data in rest operations) or other remote storage (for data in motion operations)), and/or the encryption time. More specifically, the awareness enginemay recommend performing the encryption operation at a time when the energy cost is low or is expected to be low and that the encryption operation be initiated in a particular time window and that encryption should be performed using a particular encryption module.

120 If the awareness engineis able to select the energy source or understand the potential energy costs, embodiments of the invention can balance encryption operations and energy costs. For example, a customer may desire to perform the encryption operation when a renewable energy source is contributing to the grid, even if more expensive. For example, a particular data storage array may be powered by renewable energy and a policy may be to use that energy source regardless of cost or as long as anticipated energy cost is below a threshold energy cost.

106 116 126 The models,, andcan be deployed to a data source such as a storage array or to an encryption engine. Embodiments of the invention also allow other policies to be considered when selecting a time for performing an operation for data.

2 FIG. 2 FIG. 202 208 204 204 214 216 214 216 204 204 202 discloses aspects of a system configured to encrypt data at rest and/or data in motion in an energy aware manner.illustrates an applicationthat may read/write datastored in a local storage system. The local storage systemmay be associated with remote storage systems, represented by storage arraysand. For example, the storage arraysandmay be replicas of the local storage systemor may store snapshots or backups of the local storage systemor of the application.

204 212 208 208 204 204 The local storage systemmay include or be associated with an encryption enginethat is configured to encrypt the datain the process of committing the datato storage in the local storage systemor when the data is at rest in the local storage system.

204 204 214 In another example, data stored in the local storage systemmay not be encrypted. However, prior to being transmitted from the local storage systemto the storage arrayor other target storage system, the data may be encrypted.

2 FIG. More generally,represents scenarios where data at rest encryption operations and/or data in motion encryption operations are performed. Some embodiments may include only data at rest encryption while other embodiments may include only data in motion encryption.

204 212 206 204 Although the local storage system, encryption engine, and awareness engineare illustrated separately, they may be integrated and be part of the same component, such as the storage system.

106 116 126 206 206 206 The models (e.g., models,, and) in the awareness enginemay be used to generate a recommendation regarding an encryption time and/or an encryption module. For example, in the context of a data at rest operation, the awareness enginemay predict a time required to perform a data at rest encryption operation, a time or time window in which to commence the data at rest encryption operation, and/or an encryption module. In another example, in the context of a data in motion encryption operation, the awareness enginemay recommend a time required to perform the data in motion encryption operation, a time or time window in which to commence the data in motion encryption operation, and/or a recommended encryption module.

210 206 212 210 212 210 210 212 202 210 206 Implementing the recommendationgenerated by the awareness enginemay be performed by the encryption engine. If the recommendationinclude various options, the encryption enginemay select an option from the recommendation. For example, if the recommendationincludes a time window, the encryption enginemay commence the encryption operation during the time window when available resources are above a threshold level. Alternatively, the application(or customer) may make decision regarding the options included in the recommendationprovided by the awareness engine.

210 206 206 212 206 212 204 202 The recommendationgenerated by the awareness enginemay include or account for an anticipated energy cost. Using current weather data (which may include forecasted weather data), energy costs, anticipated energy costs, energy production levels or anticipated energy production levels, source storage array locations, target storage array location, and/or other input, the models included the awareness enginemay enable the encryption engineto select a best time to perform or commence the encryption operation. Weather forecasts, energy forecasts, and the like may allow the awareness engineto generate multiple combinations of encryption times/energy costs. This allows the encryption engine(or more generally the storage systemor application) to select a specific combination or option of encryption time/energy cost that suits multiple policies including an energy policy.

206 206 212 210 206 For example, the awareness enginemay indicate a first energy cost that leverages renewable energy production if the encryption operation commences at noon (the first encryption time). The awareness enginemay indicate a second cost when less renewable energy is being produced if the encryption commences at 1 pm. This presents several options. For example, the first cost may be higher than the second cost while, at the same time, the first encryption time requirement (time to perform the encryption operation) is longer than the second encryption time requirement. The encryption enginemay consider these predictions or estimates as well as other encryption policies when executing the encryption operation in light of the recommendationgenerated by the awareness engine.

204 212 206 210 206 212 204 Thus, the storage system, or the encryption engine, may communicate with the awareness engineto obtain a recommendationor inference regarding a data at rest encryption operation and/or a data in motion encryption operation. In one example, the awareness engineand the encryption engineare part of or components of the storage system.

3 FIG.A 3 FIG.A 302 304 302 304 302 320 304 304 322 308 308 304 324 308 304 discloses aspects of a method for performing a data at rest encryption operation.illustrates a client(e.g., a user, customer, application) and a local storage array. The clientmay consume or use (read/write) data stored in the local storage array. For example, the clientmay senda data block to the storage array. The storage array(or an encryption engine) may request an encryption recommendationfrom an awareness engine. The awareness engineis configured to recommend, to the local storage array, an encryption time and/or an encryption module. Thus, the encryption information(or recommendation) returned by the awareness enginemay enable the storage arrayto make a decision regarding the encryption operation.

310 312 304 308 310 310 328 310 312 332 In this example, the encryption modulemay provide a best quality encryption, a high execution time and the encryption modulemay provide a lower quality encryption at a lower encryption time. The storage arraymay also be subject to other policies. For example, the encryption operation may need to be completed by a certain time. If the encryption time (time to perform the encryption operation) received from awareness enginesuggests that the encryption modelcan meet this requirement, then the encryption moduleis used to encrypt the data block and the encrypted block is returned in the response. If the encryption modulecannot satisfy the time requirement, an available encryption module, such as the encryption moduleis used to encrypt the data block and the encrypted data block is returned in the response.

304 338 340 308 304 338 340 Thus, the storage arraymay have options, as illustrated by the optionand the option. These options may also include energy awareness information or account for energy awareness. For example, the response or recommendation from the awareness enginemay provide energy costs associated with various encryption start times (or time windows) for each of multiple modules in which a lowest cost will be achieved or in which renewable energy is favored. The decision of which encryption module to use may depend on an energy policy (e.g., favor renewable energy), encryption quality, completion requirements, or the like. Thus, the storage arrayor encryption engine may select an encryption module from one of various options included in the recommendation represented by the optionsand.

302 308 304 304 308 For example, a policy associated with the clientmay favor renewable energy even if energy cost is more. The awareness enginemay consider aspects related to the production of renewable energy such as current weather conditions (e.g., cloudy, time of day) or the like. In this example, the arraymay be powered by renewable energy (or connected to a grid that uses renewable energy). If the weather is poor, the energy cost associated the storage arraymay be above a threshold and, where possible, the encryption operation may be delayed. If the energy cost is not over a threshold cost, in one example, the encryption operation may be performed even if the energy cost using non-renewable energy is lower at a different time. Alternatively, the awareness enginemay consider the energy delivered to the grid generally from renewable and non-renewable energy sources.

308 308 302 320 More generally, the awareness enginemay be configured to estimate the cost of energy at various times. Thus, the awareness enginemay recommend a particular time or time window during which the encryption operation should be performed to incur the lowest energy cost. If multiple options are provided (e.g., multiple time windows and corresponding anticipated energy cost), the client(or encryption engine) may be able to select the option that best satisfies all policies associated with the encryption operation. As previously stated, the ability to select any encryption option may be limited by the urgency of the request. For example, the requestmay indicate that the data is required to be encrypted in the next 20 minutes (or other requirement) These factors may suggest that encryption is performed using any available encryption module regardless of the recommendation generated by the awareness engine.

3 FIG.B 3 FIG.B 350 352 354 356 360 discloses additional aspects of a data in motion encryption operation. The decryption in motion operation ofis described in the context a local storage array, an awareness engine, an encryption module, a decryption module, and a target storage array, which is remote from the target storage array.

352 350 The awareness enginemay identify or recommend one of multiple available encryption modules, an encryption time for each of the encryption modules, energy awareness data, or the like. Each of the encryption modules are associated with a corresponding decryption module. The storage arraymay be able to select from one of multiple options.

3 FIG.B 350 362 352 364 352 364 354 366 356 368 370 360 352 In, the storage arrayrequestsa recommendation from the awareness engine. The responsefrom the awareness enginemay identify different energy aware recommendations. In this example, the responseincludes a recommendation to use the encryption module. Thus, the data block is sentto the encryption module. The encrypted data block is receivedby the storage array and the encrypted data block is transferredto the target storage array, which also may have been recommended by the awareness engine.

360 356 354 372 374 360 350 352 378 380 The target storage arrayuses a decryption module, which corresponds to the encryption module, to decryptthe data block. The decrypted data blockis received and stored at the target storage array. An acknowledgment that the data block has been successfully decrypted and stored is provided to the source storage array. A similar method would be followed if the awareness enginehad recommended an encryption module(and corresponding decryption module). Further, these may have been presented as options.

352 In this example, the encryption time recommended by the awareness engineaccounts for energy cost, energy source, aspects of the encryption operation, and/or the like. The recommendation may also account for or identify a target storage array when considering the energy considerations. For example, the encryption time may correspond to a time during which energy costs are reduced or less expensive. This may be based on current weather conditions, forecasted conditions, current energy production, forecasted energy prediction, or other conditions that may impact the cost of energy. In one example, the location of the energy source and/or the source/target storage arrays may also be considered. The recommended encryption time may correspond to a time when a renewable energy source is online and producing renewable energy.

352 352 Thus, the response or recommendation from the awareness enginemay account for the energy source and/or energy cost, source storage array, target storage array, or the like in providing the encryption time. The response or recommendation may, alternately, provide an energy assessment separately. For example, the response may identify anticipated energy costs for multiple times (multiple time windows). This allows the encryption engine to select an option that is cost-effective while also complying with or accommodating other policies. For example, it may be necessary to start an encryption operation within a certain time limit (e.g., before midnight). Thus, the encryption engine will select an option whose encryption time complies with this policy as well. The encryption models of the awareness engine, which may be trained to predict or infer energy cost based on weather data, grid data, and the like, allows the encryption operation to be performed in an energy aware manner.

As apparent from this disclosure, an embodiment of the invention may possess various useful features and aspects, although no embodiment is required to possess any of such features or aspects. Embodiments of the invention may include or relate to encryption operations, decryption operations, energy awareness related operations, energy aware encryption operations, data at rest encryption operations, data in motion encryption operations, or the like. Embodiments of the invention may relate to any operations related to encrypting data in an energy aware manner.

Following are some further example embodiments of the invention. These are presented only by way of example and are not intended to limit the scope of the invention in any way.

Embodiment 1. A method comprising: requesting a recommendation for performing a data at rest encryption operation to encrypt data at a storage system, wherein the recommendation is requested from an awareness engine that includes an encryption model configured to estimate an encryption time, wherein the recommendation includes the encryption time and/or an encryption module, encrypting the data using the encryption module recommended by an awareness engine and according to the encryption time, wherein the encryption time determined by the awareness engine accounts for an energy cost associated with performing the data at rest encryption operation, and storing the encrypted data at the storage system.

Embodiment 2. The method of embodiment 1, wherein the encryption time comprises an encryption time window and an estimated time to perform the encryption operation.

Embodiment 3. The method of embodiment 1 and/or 2, further comprising generating the encryption time by inputting features including weather features, and features of the storage system into a trained encryption module configured to predict the encryption time.

Embodiment 4. The method of embodiment 1, 2, and/or 3, further comprising waiting for the encryption time window to arrive prior to performing the encryption operation.

Embodiment 5. The method of embodiment 1, 2, 3, and/or 4, wherein the encryption time is generated by at least one machine learning model trained on data associated with historical data at rest encryption operations, historical energy costs, and factors influencing the energy costs.

Embodiment 6. The method of embodiment 1, 2, 3, 4, and/or 5, further comprising accounting for a source of energy or an estimated cost of the energy when performing the encryption operation.

Embodiment 7. The method of embodiment 1, 2, 3, 4, 5, and/or 6, wherein the encryption time is associated with lower energy costs.

Embodiment 8. The method of embodiment 1, 2, 3, 4, 5, 6, and/or 7, further comprising recommending the encryption module from among a plurality of available encryption modules.

Embodiment 9. The method of embodiment 1, 2, 3, 4, 5, 6, 7, and/or 8, further comprising performing the data at rest encryption operation with an available encryption module when the recommended encryption module does not satisfy encryption requirements of the storage system.

Embodiment 10. A method comprising: requesting a recommendation for performing a data in motion encryption operation at a storage system, wherein the recommendation is requested from an awareness engine that includes an encryption model configured to estimate an encryption time, wherein the recommendation includes the encryption time and/or an encryption module, encrypting the data using the encryption module recommended by the awareness engine and according to the encryption time, wherein the encryption time determined by the awareness engine accounts for an energy cost associated with performing the data at rest encryption operation, transmitting the encrypted data to a target storage system, decrypting the encrypted data at the target storage system, and storing the decrypted data at the target storage system.

Embodiment 11. The method of embodiment 11, wherein the encryption time comprises an encryption window and an estimated time to perform the encryption operation.

Embodiment 12. The method of embodiment 10 and/or 11, further comprising generating the encryption time by inputting features including weather features, and features of the storage system into a trained encryption module configured to predict the encryption time.

Embodiment 13. The method of embodiment 10, 11, and/or 12, further comprising waiting for the encryption time window to arrive prior to performing the encryption operation.

Embodiment 14. The method of embodiment 10, 11, 12, and/or 13, wherein the encryption time is generated by at least one machine learning model trained on data associated with historical data in motion encryption operations, historical energy costs, and factors influencing the energy costs.

Embodiment 15. The method of embodiment 10, 11, 12, 13, and/or 14, further comprising accounting for a source of energy or an estimated cost of the energy when performing the data in motion encryption operation.

Embodiment 16. The method of embodiment 10, 11, 12, 13, 14, and/or 15, wherein the encryption time is associated with lower energy costs.

Embodiment 17. The method of embodiment 10, 11, 12, 13, 14, 15, and/or 16, further comprising recommending the encryption module from among a plurality of available encryption modules.

Embodiment 18. The method of embodiment 10, 11, 12, 13, 14, 15, 16, and/or 17, further comprising performing the data in motion encryption operation with an available encryption module when the recommended encryption module does not satisfy encryption requirements of the storage system.

Embodiment 19. A method comprising: requesting a recommendation for performing an encryption operation to encrypt data at a storage system, wherein the recommendation is requested from an awareness engine that includes an encryption model configured to estimate an encryption time, wherein the recommendation includes the encryption time and/or an encryption module, encrypting the data using the encryption module recommended by the awareness engine and according to the encryption time, wherein the encryption time determined by an awareness engine accounts for an energy cost associated with performing the data at rest encryption operation, and storing the encrypted data at the storage system.

19 Embodiment 20. The method of claim, further comprising transmitting the encrypted data to a target storage system, decrypting the encrypted data, and storing the decrypted data at the target storage system.

Embodiment 21. A system, comprising hardware and/or software, operable to perform any of the operations, methods, or processes, or any portion of any of these, disclosed herein.

Embodiment 21. A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising the operations of any one or more of embodiments 1-20.

The embodiments disclosed herein may include the use of a special purpose or general-purpose computer including various computer hardware or software modules, as discussed in greater detail below. A computer may include a processor and computer storage media carrying instructions that, when executed by the processor and/or caused to be executed by the processor, perform any one or more of the methods disclosed herein, or any part(s) of any method disclosed.

As indicated above, embodiments within the scope of the present invention also include computer storage media, which are physical media for carrying or having computer-executable instructions or data structures stored thereon. Such computer storage media may be any available physical media that may be accessed by a general purpose or special purpose computer.

By way of example, and not limitation, such computer storage media may comprise hardware storage such as solid state disk/device (SSD), RAM, ROM, EEPROM, CD-ROM, flash memory, phase-change memory (“PCM”), or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other hardware storage devices which may be used to store program code in the form of computer-executable instructions or data structures, which may be accessed and executed by a general-purpose or special-purpose computer system to implement the disclosed functionality of the invention. Combinations of the above should also be included within the scope of computer storage media. Such media are also examples of non-transitory storage media, and non-transitory storage media also embraces cloud-based storage systems and structures, although the scope of the invention is not limited to these examples of non-transitory storage media.

Computer-executable instructions comprise, for example, instructions and data which, when executed, cause a general purpose computer, special purpose computer, or special purpose processing device to perform a certain function or group of functions. As such, some embodiments of the invention may be downloadable to one or more systems or devices, for example, from a website, mesh topology, or other source. As well, the scope of the invention embraces any hardware system or device that comprises an instance of an application that comprises the disclosed executable instructions.

Although the subject matter has been described in language specific to structural features and/or methodological acts, it is to be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts disclosed herein are disclosed as example forms of implementing the claims.

As used herein, the term client, module, component, engine, agent, service, or the like may refer to software objects or routines that execute on the computing system or may also refer to hardware depending on context. These may be implemented as objects or processes that execute on the computing system, for example, as separate threads. While the system and methods described herein may be implemented in software, implementations in hardware or a combination of software and hardware are also possible and contemplated. In the present disclosure, a ‘computing entity’ may be any computing system as previously defined herein, or any module or combination of modules running on a computing system.

In at least some instances, a hardware processor is provided that is operable to carry out executable instructions for performing a method or process, such as the methods and processes disclosed herein. The hardware processor may or may not comprise an element of other hardware, such as the computing devices and systems disclosed herein.

In terms of computing environments, embodiments of the invention may be performed in client-server environments, whether network or local environments, or in any other suitable environment. Suitable operating environments for at least some embodiments of the invention include cloud computing environments, which may be remote or on-prem, where one or more of a client, server, or other machine may reside and operate in a cloud environment.

4 FIG. 4 FIG. 400 With reference briefly now to, any one or more of the entities disclosed, or implied, the Figures and/or elsewhere herein, may take the form of, or include, or be implemented on, or hosted by, a physical computing device, one example of which is denoted at. As well, where any of the aforementioned elements comprise or consist of a virtual machine (VM), that VM may constitute a virtualization of any combination of the physical components disclosed in.

4 FIG. 400 402 404 406 408 410 412 402 400 414 406 In the example of, the physical computing deviceincludes a memorywhich may include one, some, or all, of random access memory (RAM), non-volatile memory (NVM)such as NVRAM for example, read-only memory (ROM), and persistent memory, one or more hardware processors, non-transitory storage media, UI device, and data storage. One or more of the memory componentsof the physical computing devicemay take the form of solid state device (SSD) storage. As well, one or more applicationsmay be provided that comprise instructions executable by one or more hardware processorsto perform any of the operations, or portions thereof, disclosed herein.

Such executable instructions may take various forms including, for example, instructions executable to perform any method or portion thereof disclosed herein, and/or executable by/at any of a storage site, whether on-premises at an enterprise, or a cloud computing site, client, datacenter, data protection site including a cloud storage site, or backup server, to perform any of the functions disclosed herein. As well, such instructions may be executable to perform any of the other operations and methods, and any portions thereof, disclosed herein.

400 400 The devicemay also be representative of servers, clusters of servers, nodes, or the like. The computing resources represented by the devicemay represent the computing resources of a cloud provider that can be allocated or used for energy aware compression operations.

The present invention may be embodied in other specific forms without departing from its spirit or essential characteristics. The described embodiments are to be considered in all respects only as illustrative and not restrictive. The scope of the invention is, therefore, indicated by the appended claims rather than by the foregoing description. All changes which come within the meaning and range of equivalency of the claims are to be embraced within their scope.

Classification Codes (CPC)

Cooperative Patent Classification codes for this invention. Click any code to explore related patents in that topic.

Patent Metadata

Filing Date

January 24, 2024

Publication Date

August 4, 2026

Inventors

Aidan O'Mahony
Ahmed Khalid
Alan Barnett
Stephen J. Todd

Want to explore more patents?

Browse 5M+ US patents with plain-English claim translations and AI-generated analysis.

Citation & reuse

Analysis on this page is generated by Patentable — an AI-powered patent intelligence platform. AI-generated summaries, explanations, and analysis may be reused with attribution and a visible link back to the canonical URL below. Patent abstracts and claims are USPTO public domain.

Cite as: Patentable. “Encrypting data at rest and data in motion with trustworthy energy awareness” (US-12699783-B2). https://patentable.app/patents/US-12699783-B2

© 2026 Patentable. All rights reserved.

Patentable is a research and drafting-assistant tool, not a law firm, and does not provide legal advice. Documents we generate are drafts for review by a licensed patent attorney.

Encrypting data at rest and data in motion with trustworthy energy awareness — Aidan O'Mahony | Patentable